Privacy policy
Last reviewed: 2026-08-20
This is a translation for convenience. In case of doubt, the German version is authoritative.
This notice explains what happens to personal data when you use the ZombyIO website, the dashboard and the Discord bot. It describes what the software actually does.
Who is responsible
The controller within the meaning of the GDPR is the provider named in the imprint. A data protection officer is not required and has not been appointed.
Tim VidaIn den Zeuläckern 20
60389 Frankfurt am Main
Deutschland
info@zomby.io
Where it runs
The website, the dashboard, the bot and the database run on a server operated by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, in a data centre in Germany. Hetzner processes the data on our behalf under a data processing agreement pursuant to Art. 28 GDPR. The domain is registered with STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin.
Visiting the site
Each request is recorded with the IP address, the time, the requested address, the referring page and the browser identification, so the service can be delivered and attacks can be recognised. Legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in operating the service securely. These records are kept for a short period and then deleted.
Cookies
ZombyIO uses only cookies that are strictly necessary for the functions you asked for. There is no tracking, no advertising, no analytics and no third-party cookie. Nothing here builds a profile of you.
Because every cookie below is strictly necessary to provide the service you requested, no consent is required for them under § 25 (2) no. 2 TDDDG. Legal basis for the associated processing is Art. 6 (1) (b) GDPR for the login and Art. 6 (1) (f) GDPR for the display preferences. You can delete cookies at any time in your browser; the login and your saved preferences will then be lost.
| Name | Purpose | Lifetime |
|---|---|---|
__Host-zomby_session | Keeps you signed in after logging in with Discord. | 30 days |
__Host-zomby_oauth_state | Protects the login against cross-site request forgery. | 10 minutes |
__Host-zomby_oauth_next | Remembers the page to return to after logging in. | 10 minutes |
__Host-zomby_twitch_state | Protects connecting a Twitch channel against cross-site request forgery. | 10 minutes |
__Host-zomby_twitch_next | Remembers the page to return to after connecting Twitch. | 10 minutes |
__Host-zomby_twitch_linked | Names the Twitch channel you just connected, so the page can show the result. | 30 minutes |
__Host-zomby_twitch_mode | Remembers which kind of Twitch connection you started: as a streamer, as a viewer, or for a drops campaign. | 10 minutes |
zomby_locale | Remembers the language you chose. | 1 year |
zomby_panels | Remembers which settings sections you folded away. | 1 year |
zomby_notice | Remembers that you have seen the note about cookies. | 1 year |
Your account
Logging in happens through Discord. We receive and store your Discord user id, your username, your avatar and your language setting, and which servers you may administer. Your Discord access token is stored encrypted with AES-256-GCM so the dashboard can act on your behalf. For each active session we also store the browser identification and the time of last use, so that you can recognise and end sessions on the settings page. Legal basis is Art. 6 (1) (b) GDPR, performance of the contract you enter into by using the dashboard.
Server data
For each Discord server the bot is on, we store the settings configured in the dashboard, moderation cases with the reason and the Discord ids involved, and members’ experience point totals. Everything is keyed by Discord id; we do not store names or email addresses of your members. Legal basis is Art. 6 (1) (f) GDPR, the legitimate interest of the server operator in moderating their community.
Message content
Auto moderation examines the text of messages in the bot’s working memory to decide whether a rule applies, and discards it immediately afterwards. Message content is never written to the database. If a rule fires, what is recorded is the rule that matched and a short extract of what matched it, not the message.
Connected Twitch channels
Streamers can connect their own Twitch account on our connect page so that their go-live reaches the Discord servers that follow them instantly. We store the Twitch channel id, the channel name and the display name, all of which are already public on the channel page, together with the permission Twitch reported and the times of connecting and last confirming. We do not store the access token, we do not store a refresh token, and we do not read the email address, even though the permission Twitch requires for recording a connection would allow it. Legal basis is Art. 6 (1) (a) GDPR, consent, given by the authorisation on Twitch. Withdrawing it under Connections in your Twitch settings is passed to us by Twitch and we delete the record.
Stream Drops: watchtime and rewards
On servers that run a Stream Drops campaign, viewers can link their own Twitch account to their ZombyIO account. We store the Twitch account id, the login name and the display name; no token is stored and we do not read the email address. While a connected streamer is live, we read from Twitch the public list of who is in the channel’s chat and credit watchtime to linked viewers. Per server we store the seconds watched today, this month and in total, the last time the viewer was seen watching, and whether the viewer is still on the Discord server. Being in the audience is enough; nothing anyone writes in the chat is read. Legal basis is Art. 6 (1) (a) GDPR, consent, given by linking the account.
Every drop received is stored with its kind, its cause, its label and the reward itself, including a gift code the viewer won, together with the time, and is shown only to the viewer themselves; the bot announces it by direct message. Gift codes an administrator stocks are stored until they are handed out; the winner’s claim is recorded. A role granted for a limited time is stored with server, role and expiry until the role is removed again. That record is the one exception to deletion: it survives the erasure of the account so that the temporary role still expires instead of becoming permanent. Everything else, the Twitch link, all watchtime and the entire drop history, is deleted with the ZombyIO account and is included in the data export on the settings page.
Payments
Premium subscriptions are processed by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Payment is made on Stripe’s own pages; card details never reach our servers. We store only the Stripe customer and subscription identifiers and the state of the subscription. Legal basis is Art. 6 (1) (b) GDPR.
Discord
ZombyIO is a Discord application and cannot work without exchanging data with Discord. Discord is the controller for its own processing; for users in the EEA this is Discord Netherlands B.V., with its parent Discord Inc. in the United States. In the dashboard, avatars and server icons are loaded directly from Discord’s content network, which means your IP address reaches Discord at that moment. Discord’s own privacy policy applies to everything Discord does with it.
Transfers outside the EU
Data reaching Discord and Stripe may be processed in the United States. Those transfers are based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.
How long we keep things
- Session: 30 days after signing in, or immediately when you log out.
- Server data: deleted 90 days after ZombyIO is removed from that server.
- Moderation cases: kept while the bot is on the server, so a case history stays meaningful.
- Billing records: kept as long as required by commercial and tax law.
Your rights
Under the GDPR you have the right to:
- access the data we hold about you (Art. 15),
- have inaccurate data corrected (Art. 16),
- have your data deleted (Art. 17),
- have processing restricted (Art. 18),
- receive your data in a portable format (Art. 20),
- object to processing based on legitimate interests (Art. 21).
Access, portability and erasure are self-service: on the settings page of the dashboard you can download your data as a file and delete your account yourself. For everything else, write to the address in the imprint or to the email address above. We answer within one month.
Complaints
You may complain to a supervisory authority. The one responsible for us is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden.
Is providing data required?
You do not have to provide anything. Without a Discord login there is no dashboard, and without the settings you enter the bot has nothing to act on; there is no other consequence.
Changes
When the software changes in a way that changes this notice, the notice is updated with it. The date above says when it was last reviewed.